gnuchess could be made to crash or run programs as your login if it opened a specially crafted file.. ========================================================================== Ubuntu Security Notice USN-7336-1 March 06, 2025 gnuchess vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: gnuchess could be made to crash or run programs as your login if it opened a specially crafted file. Software Description: - gnuchess: Plays a game of chess, either against the user or against itself Details: Michael Vaughan discovered an overflow vulnerability in GNU Chess that occurs when reading a specially crafted Portable Game Notation (PGN) file. An attacker could possibly use this issue to cause GNU Chess to crash, resulting in a denial of service, or the execution of arbitrary code. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.10 gnuchess 6.2.7-1+deb11u1build0.24.10.1 Ubuntu 24.04 LTS gnuchess 6.2.7-1+deb11u1build0.24.04.1 Ubuntu 22.04 LTS gnuchess 6.2.7-1+deb11u1build0.22.04.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7336-1 CVE-2021-30184 Package Information: https://launchpad.net/ubuntu/+source/gnuchess/6.2.7-1+deb11u1build0.24.10.1 https://launchpad.net/ubuntu/+source/gnuchess/6.2.7-1+deb11u1build0.24.04.1 https://launchpad.net/ubuntu/+source/gnuchess/6.2.7-1+deb11u1build0.22.04.1 . This alert highlights a vulnerability in gnuchess present across various Ubuntu distributions, which may lead to unauthorized code execution.. Ubuntu Security, gnuchess Issue, CodeExecution Risk. . LinuxSecurity.com Team
An issue has been found in gnuchess, a tool to play a game of chess, either against the user or against itself. The issue is related to arbitrary code execution via crafted PGN (Portable . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4014-1
Patch for CVE-2021-30184.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-ff3297913b 2021-04-24 20:00:51.078831 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 34 Version : 6.2.7 Release : 5.fc34 URL : Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: Patch for CVE-2021-30184. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 8 2021 Gwyn Ciesla - 6.2.7-5 - Patch for CVE-2021-30184 --------------------------------------------------------------------------------References: [ 1 ] Bug #1947594 - CVE-2021-30184 gnuchess: buffer overflows in the cmd_pgnload() and cmd_pgnreplay() functions in frontend/cmd.cc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1947594 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-ff3297913b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Patch for CVE-2021-30184.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-a58cb9bc7a 2021-04-16 14:42:40.037684 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 32 Version : 6.2.7 Release : 5.fc32 URL : Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: Patch for CVE-2021-30184. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 8 2021 Gwyn Ciesla - 6.2.7-5 - Patch for CVE-2021-30184 * Tue Jan 26 2021 Fedora Release Engineering - 6.2.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild * Sat Aug 1 2020 Fedora Release Engineering - 6.2.7-3 - Second attempt - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild * Mon Jul 27 2020 Fedora Release Engineering - 6.2.7-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_33_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1947594 - CVE-2021-30184 gnuchess: buffer overflows in the cmd_pgnload() and cmd_pgnreplay() functions in frontend/cmd.cc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1947594 --------------------------------------------------------------------------------This update can be installed with the "dnf" updateprogram. Use su -c 'dnf upgrade --advisory FEDORA-2021-a58cb9bc7a' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Patch for CVE-2021-30184.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2021-2c714d311f 2021-04-16 14:33:16.807827 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 33 Version : 6.2.7 Release : 5.fc33 URL : Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: Patch for CVE-2021-30184. --------------------------------------------------------------------------------ChangeLog: * Thu Apr 8 2021 Gwyn Ciesla - 6.2.7-5 - Patch for CVE-2021-30184 * Tue Jan 26 2021 Fedora Release Engineering - 6.2.7-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_34_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1947594 - CVE-2021-30184 gnuchess: buffer overflows in the cmd_pgnload() and cmd_pgnreplay() functions in frontend/cmd.cc [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1947594 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2021-2c714d311f' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. Moredetails on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
6.2.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-dbccd7e9be 2020-04-27 04:47:02.527567 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 31 Version : 6.2.6 Release : 1.fc31 URL : ftp://ftp.gnu.org/pub/gnu/chess/ Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: 6.2.6 --------------------------------------------------------------------------------ChangeLog: * Sun Apr 19 2020 Gwyn Ciesla - 6.2.6-1 - 6.2.6 * Tue Jan 28 2020 Fedora Release Engineering - 6.2.5-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1749177 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749177 [ 2 ] Bug #1749178 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1749178 [ 3 ] Bug #1825541 - gnuchess-6.2.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1825541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program.Use su -c 'dnf upgrade --advisory FEDORA-2020-dbccd7e9be' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
6.2.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-3eaf264c4b 2020-04-27 03:06:12.192800 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 30 Version : 6.2.6 Release : 1.fc30 URL : ftp://ftp.gnu.org/pub/gnu/chess/ Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: 6.2.6 --------------------------------------------------------------------------------ChangeLog: * Sun Apr 19 2020 Gwyn Ciesla - 6.2.6-1 - 6.2.6 * Tue Jan 28 2020 Fedora Release Engineering - 6.2.5-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_32_Mass_Rebuild * Thu Jul 25 2019 Fedora Release Engineering - 6.2.5-9 - Rebuilt for https://fedoraproject.org/wiki/Fedora_31_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1749177 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749177 [ 2 ] Bug #1749178 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1749178 [ 3 ] Bug #1825541 - gnuchess-6.2.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1825541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-3eaf264c4b' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
6.2.6. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2020-8083181df6 2020-04-27 02:43:13.375330 --------------------------------------------------------------------------------Name : gnuchess Product : Fedora 32 Version : 6.2.6 Release : 1.fc32 URL : ftp://ftp.gnu.org/pub/gnu/chess/ Summary : The GNU chess program Description : The gnuchess package contains the GNU chess program. By default, GNU chess uses a curses text-based interface. Alternatively, GNU chess can be used in conjunction with the xboard user interface and the X Window System for play using a graphical chess board. Install the gnuchess package if you would like to play chess on your computer. If you'd like to use a graphical interface with GNU chess, you'll also need to install the xboard package and the X Window System. --------------------------------------------------------------------------------Update Information: 6.2.6 --------------------------------------------------------------------------------ChangeLog: * Sun Apr 19 2020 Gwyn Ciesla - 6.2.6-1 - 6.2.6 --------------------------------------------------------------------------------References: [ 1 ] Bug #1749177 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1749177 [ 2 ] Bug #1749178 - CVE-2019-15767 gnuchess: stack-based overflow in cmd_load in frontend/cmd.cc via crafted EPD file [epel-7] https://bugzilla.redhat.com/show_bug.cgi?id=1749178 [ 3 ] Bug #1825541 - gnuchess-6.2.6 is available https://bugzilla.redhat.com/show_bug.cgi?id=1825541 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2020-8083181df6' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.